I agree. One solution is "have a real human identity you can't delegate with real stakes if you're banned." What we need is a blue checkmark for everyday people.
I agree. One solution is "have a real human identity you can't delegate with real stakes if you're banned." What we need is a blue checkmark for everyday people.
Most times, harassers are protected by their legal system, not the victims. But if someone dares insult the police, then they'll find you in a second and put you on trial.
We need better tools to manage trust and consent in a decentralized settings without revealing the social graph. I heard the expression "Fog of Trust" a few times to refer to that.
Such policies have definitely not cut back on spam (at least not according to my definition of spam), but have prevented countless legit users like me from taking part in such networks. Retrospectively it's a good thing that these networks don't want people like me, we're doing much better elsewhere.
I propose you a challenge: if you can view age-restricted videos on Youtube and create a Facebook group without giving your ID, credit card, address, phone number or IP address... i'll send you a cupcake over mail? :P
1. User registers a non-transferable username (maybe an NFT?)
2. User signs into the client with the username NFT
3. The server admin maintains a list of shadowbanned username NFTs -- if yours gets added, then the server won't relay your messages.
Non-transferability means no one will squat usernames (since there's no money to be made by reselling them), and since it costs money to register but costs nothing to shadowban, the asshats only lose money by being asshats (and their spam doesn't even get read).
To achieve this, it would be sufficient to make it so the cost of registering a user account is asymptotically more expensive than the cost of shadowbanning an account. If the software required that each additional account a user registers costs more in USD terms than the previous account, while keeping the cost of shadowbanning a username constant, then the honest participants will win in a struggle against asshats who must keep registering accounts to circumvent the shadowban.
A strawman approach would be to require all user accounts to be tied to real-world identities. Then, the software can track how many accounts a real-world person has registered, and bill them accordingly. This obviously has other unrelated problems, but it does make it possible to penalize asshats more and more harshly for each infraction.
I was suggesting that a blockchain could be a useful building block here, since it already exists, is widely deployed, and costs money to write state. A more practical approach than the strawman could be to implement a username registration system on a blockchain, such that each registrant must burn some of the blockchain's tokens to register a username (thereby imposing a cost to doing so). Crucially, the number of tokens burnt per name would increase as more and more usernames get registered (or as more and more time passes), and in doing so make it more and more costly for asshats to circumvent a shadowban. This would also make it so asshats would lose a war of attrition against admins, and could be implemented today.
This is just a tax on the young.
It sounds like all you've actually invented is "identifying people by their bank accounts", only with more steps.
I suppose if the NFT could be registered using an anonymous cryptocurrency, it might end up being a more privacy-preserving system than getting people to pay for an account using traditional methods.
It also might be cheaper than paying to join multiple services, if you only have to pay once and can use your NFT username across them all. On the other hand, a single malicious admin could try to extort you by threatening to ban you from all those other services.
A better approach would be a blockchain-based anonymous identity system, which is apparently what BrightID is:
Trivially. You make it so that there's no recognized way to change the private key for a username.
> It sounds like all you've actually invented is "identifying people by their bank accounts", only with more steps.
I've created a layer of indirection between usernames and bank accounts. The system doesn't need to know or care about how you managed to burn tokens for the username.
> A better approach would be a blockchain-based anonymous identity system, which is apparently what BrightID is:
Does BrightID guarantee that asshats have an asymptotically worse time registering usernames than admins have shadowbanning them? If usernames are easy to come by, then so are sockpuppets and one-off spam and troll accounts.
Making it impossible to rotate keys doesn't sound like it follows cryptographic best practices, but in any case, there's nothing stopping someone from selling their private key to someone else.
If you just want to avoid squatting/speculating, you could make the user IDs be random unique values but associate them with a non-unique human-readable name.
> If usernames are easy to come by, then so are sockpuppets and one-off spam and troll accounts.
I haven't used BrightID, but I believe it works by having users meet in person and mutually verify each other as being unique humans. It should be impossible for someone to pretend to be two people in the same place at the same time, so that does seem viable.
The fact that the original owner(s) can still use the name would prevent resale. For example, the admins could simply shadowban a username if they verify that multiple users have the same key (e.g. if my private key was stolen, I'd report it to the admin).
> If you just want to avoid squatting/speculating, you could make the user IDs be random unique values but associate them with a non-unique human-readable name.
The literal identifier isn't important to account resale value. User accounts include all of the state as well as the literal identifier, including reputation, longevity, and associated app content. This is all valuable to asshats -- they want high-reputation accounts to broaden their spam audience. But in order to make it costly for asshats to gain high-reputation accounts (more costly for them than for admins to shadowban them), we can't give them any shortcuts -- the system should compel them to spend time and energy to earn their reputation like everyone else. So, account resale shouldn't be supported by the system.
> I believe it works by having users meet in person and mutually verify each other as being unique humans. It should be impossible for someone to pretend to be two people in the same place at the same time, so that does seem viable.
This does not sound like it prevents a small number of asshats from just creating a bunch of fake sockpuppet accounts. If creating accounts is a cheap (or cheaper) than shadowbanning them, then the asshats will eventually overwhelm the admins.
The buyer would know that maybe the seller still has the key, since cannot be rotated
> user IDs be random unique values but associate them with a non-unique human-readable name.
I think scuttlebutt does something like that
> It should be impossible for someone to pretend to be two people in the same place at the same time
A group of people cooperating can pretend to be 99999 people?
If the buyer is a spammer, they won't care that the seller can still send non-spammy messages with the account. If the seller is a squatter/speculator, they have nothing to gain from interfering with their customer's account.
> A group of people cooperating can pretend to be 99999 people?
It would be easy to determine from the (anonymous) social graph that those 99999 people are only connected to each other and a small group of other (real) people. An algorithm looking at this graph could then select 100 people out of the 99999 group and require them to meet with 2 other distantly-connected people at a specified public place. If less than 102 people show up, then those 100 lose trust points. That's how I guess it would work, anyway.
What if the seller is a spammer or scammer, and first sells the account, remembers the private key, and a bit later starts spamming or scamming
> It would be easy to determine from the (anonymous) social graph that those 99999 people are only connected to each other and a small group of other (real) people
If the "group of people" is small, yes. I didn't say that the group was small though.
If it is larger, and they arrange the connections in realistic looking ways (for detection algorithms), then they can get away with it. Think of an island where most people are connected with others on the island only -- and maybe 10% of them connected to people on the mainland. Something like that can happen in real life I suppose, and the "group of people" (possibly many, paid by a company or a state) could construct such graphs and pretend to be more than what they are
> An algorithm looking at this graph could then select 100 people out of the 99999 group and require them to meet with 2 other distantly-connected people at a specified public place
That's an interesting way to try to handle that. However, first the algorithm would need to realize that a part of the graph is suspicious. (And people would need to be really motivated to, in real life, actually go to somewhere :-) ? what of they're busy with friends and family)
1. it's slow, requires insane amount of storage, power and traffic
2. nobody wants non-transferable username for real
Compared to the infrastructure required to uniquely identify every human in order to stop them from registering lots of troll accounts, and implementing a fair and accountable law enforcement apparatus to make sure the rules are followed? The blockchain might be cheaper.
> 2. nobody wants non-transferable username for real
Which is the worse outcome -- you can't transfer your username (but you can register a new one for a fee), or trolls and squatters can trash the system?
No problems with spammers or trolls at all. And that's literally my experience with 20+ homeservers that I configured
Again, nobody wants unique permanent ID per human.
PS: regarding "a new one for fee" - I hate services that work this way (hello, Blizzard), IMO.